VAPT & SOC 2 Type II Security Tester
Company: TravellerTrack
Location: Remote / Hybrid
Experience: 2–5+ years
About TravellerTrack
TravellerTrack is an enterprise mobility and corporate transportation technology platform helping organizations manage employee transportation, spot rentals, approvals, vendors, drivers, and trip operations through a centralized digital platform.
As we expand our enterprise customer base, we are looking for an experienced VAPT & SOC 2 Type II Security Professional to assess our platform and help us strengthen our security and compliance readiness.
Role Overview
We are looking for an experienced security tester/consultant who can independently conduct Vulnerability Assessment & Penetration Testing (VAPT) across our web applications, APIs, infrastructure, and relevant mobile applications, and support our SOC 2 Type II readiness and compliance requirements.
Key Responsibilities
- Conduct comprehensive VAPT of TravellerTrack's web application, APIs, mobile applications, and supporting infrastructure.
- Perform security testing based on OWASP Top 10, OWASP API Security Top 10, SANS, and industry best practices.
- Identify vulnerabilities including authentication, authorization, API security, injection, session management, access control, data exposure, business logic, and configuration issues.
- Perform vulnerability scanning and manual penetration testing.
- Assess cloud infrastructure, network configuration, databases, endpoints, and security controls where applicable.
- Validate identified vulnerabilities and provide clear evidence, risk ratings, and remediation recommendations.
- Conduct retesting after vulnerabilities are remediated.
- Review existing security policies, processes, access controls, logging, monitoring, backup, incident response, and change-management practices.
- Support TravellerTrack in preparing for SOC 2 Type II readiness/audit.
- Identify gaps against applicable SOC 2 Trust Services Criteria.
- Help establish practical security controls and documentation required for ongoing compliance.
- Provide professional reports suitable for sharing with enterprise customers and auditors.
Required Skills & Experience
- 2–5+ years of experience in cybersecurity, VAPT, penetration testing, or information security.
- Strong hands-on experience with web application and API penetration testing.
- Knowledge of OWASP Top 10 and OWASP API Security Top 10.
- Experience testing REST APIs, authentication mechanisms, authorization controls, JWT/OAuth, and role-based access.
- Experience with tools such as Burp Suite, Nmap, Nessus/OpenVAS, Postman, Metasploit, or equivalent.
- Understanding of cloud security and common SaaS security architecture.
- Strong understanding of information security principles and risk management.
- Familiarity with SOC 2, ISO 27001, security policies, controls, and audit evidence.
- Ability to prepare professional VAPT reports with severity classification and remediation guidance.
Preferred Qualifications
- OSCP, CEH, CREST, CISSP, CISA, or equivalent certifications.
- Experience working with SaaS/technology companies.
- Previous experience supporting SOC 2 Type I/Type II audits.
- Experience working with enterprise customers and their security assessment requirements.
- Familiarity with AWS/Azure/GCP security controls.
- Experience with compliance frameworks such as ISO 27001, GDPR, or similar standards.
Deliverables
The selected professional/agency will be expected to provide:
- Comprehensive VAPT assessment.
- Detailed vulnerability report with severity and evidence.
- Executive-level security summary.
- Remediation recommendations.
- Retesting/validation after remediation.
- SOC 2 readiness/gap assessment.
- Recommendations for required security controls and documentation.
- Support during security/compliance discussions where required.
What We Are Looking For
We are looking for someone who can actually perform hands-on security testing and provide audit-ready documentation, rather than only conducting automated vulnerability scans.
If you have experience conducting VAPT for SaaS platforms and supporting organizations toward SOC 2 Type II readiness, we'd love to hear from you.
Pay: ₹35,000.00 - ₹50,000.00 per month
Work Location: In person